>

APT29 Inside TeamViewer: 2024’s Calmest, Most Instructive Breach

On June 28, 2024, TeamViewer disclosed that a state-sponsored actor — widely reported as Russia's APT29 — had breached its corporate IT network through a standard employee's credentials, and that the remote-access product itself, and every customer, stayed untouched. This account reconstructs the hours-to-containment timeline, explains why corporate/product segmentation carried the day, places the intrusion in Cozy Bear's patient espionage season, and draws the anti-SolarWinds comparison that made this 2024's most instructive breach.

Continue ReadingAPT29 Inside TeamViewer: 2024’s Calmest, Most Instructive Breach

Polyfill.io Hijack: 100,000+ Sites Inherited a Malicious Script

When Sansec disclosed in late June 2024 that the polyfill.io domain had been sold and its hosted script rewritten to inject mobile-only scam redirects, hundreds of thousands of embedded sites — WordPress themes among them — discovered they had inherited an implant, invisible to desktop QA by design. This account traces the Funnull acquisition chain, the conditional payload mechanics, Cloudflare's mirror intervention, the DNS-harassment retaliation, the 2025 arrests, and the inventory lesson every site owner still owes themselves.

Continue ReadingPolyfill.io Hijack: 100,000+ Sites Inherited a Malicious Script

Brain Cipher vs Indonesia’s Data Centers: A National Ransomware Reckoning

In June 2024, the Brain Cipher crew — running a LockBit 3.0 builder clone — encrypted Indonesia's National Data Center, disrupting 200+ government services from immigration to licensing, then released a decryptor with an apology-flavored admission that extortion failed, then hit again during recovery. This account covers the copycat-crew economics behind the operation, why one shared-tenant data center meant national outage, the second-encryption lesson about persistence, and the segmented-architecture rebuild Indonesia promised next.

Continue ReadingBrain Cipher vs Indonesia’s Data Centers: A National Ransomware Reckoning

CDK Global Ransomware: US Car Dealerships Run on Pen and Paper

On June 19, 2024, ransomware hit CDK Global's dealer management platform — the operational nervous system of ~15,000 North American dealerships — and a second strike during recovery extended the outage for weeks while finance desks, service bays and OEM ordering reverted to paper and fax. This account covers the June 19/22 double-hit timeline, the billion-dollar industry loss estimates, why DMS lock-in made fallback manual rather than competitive, and the concentration-risk docket the incident left for every regulator to cite.

Continue ReadingCDK Global Ransomware: US Car Dealerships Run on Pen and Paper

The Snowflake Extortion Campaign at Its Peak: 165+ Customers, One Credential Wave

On June 19, 2024, Mandiant's public advisory named UNC5537 as the crew behind the Snowflake extortion wave — 165+ victim organizations entered with infostealer credentials against MFA-less tenants, datasets extorted through listings and a dedicated leak market researchers dubbed Snow:Bay. This piece condenses the TTP catalogue, the backyard economics of stolen logs, the aftermarket that changed notification obligations forever, and the single control that would have prevented every confirmed intrusion.

Continue ReadingThe Snowflake Extortion Campaign at Its Peak: 165+ Customers, One Credential Wave
>